Support

Admin Tools

#9676 Protect admin problem

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Tuesday, 26 October 2010 00:14 CDT

kkevents
When I use the password protect admin, It asks for the user and password in the Yootheme extension ZOO front page for my file download area. More specifically if I try to go into a zoo category for a file download area I have on my site. If I click cancel it will let me continue, but will still ask for it again and again. I have removed the password feature for now.

The link below is where the problem occurs.

http://www.kosickworld.com/pap-files

nicholas
Akeeba Staff
Manager
This is the strong indication of a poorly designed component :( After clicking on a category in that page (let's say, Printers) and tracking down the media files used in that page I can see that it directly references media files inside the administrator area, like administrator/components/com_zoo/elements/download/assets/images/download_type_doc.png. This should not happen on a properly written extension! Joomla!'s architecture calls for a separation of the public and administrator parts of a component. What Zoo does is load files directly from the administrator part. When you enable the back-end password protection feature in Admin Tools, we create a .htaccess file which requires a password to be requested whenever anyone tries to access anything inside the administrator directory. This is based on the premise that all installed extensions exercise this separation between front- and back-end. Therefore this is not a bug in Admin Tools but an architectural flaw in Zoo. Please contact YooThemes and ask them to address this issue because it ends up degrading the security of your site. If they have more questions on this matter, please ask them to contact me directly. Thanks! :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!